OpenProject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*
- <= 15.0.0
A SQL injection vulnerability has been identified in OpenProject versions prior to 17.2.3. The issue arises in the cost reporting module, where the '=n' operator embeds user input directly into SQL WHERE clauses without proper parameterization. This flaw allows authenticated users with access to cost reports to read or modify any database data.
Exploitation of this vulnerability allows authenticated users with access to cost reports to read or modify any database data.
Users are advised to update to OpenProject version 17.2.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.